Vulnerability index

Browse CVEs

287 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.0 CVE-2008-4616EPSS 7% The SpamBam plugin for WordPress allows remote attackers to bypass restrictions and add blog comments by using server-supplied values to calculate a … Spambam Plugin Mitigation only Fix from $1,6002008-10-20 MEDIUM 5.1 CVE-2008-4106EPSS 5% WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maximum column width of the user_l… WordPress after 2.6.1 Fix from $1,6002008-09-18 HIGH 7.5 CVE-2008-3747 The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL commun… WordPress Patch available Fix from $1,9502008-08-27 HIGH 10.0 CVE-2008-3362EPSS 17% Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attackers to exe… Wp Downloads Manager No fix yet Fix from $1,9502008-07-30 HIGH 7.5 CVE-2008-2510 SQL injection vulnerability in wp-uploadfile.php in the Upload File plugin for WordPress allows remote attackers to execute arbitrary SQL commands vi… Upload File Plugin Mitigation only Fix from $1,9502008-05-29 HIGH 9.0 CVE-2008-2392 Unrestricted file upload vulnerability in WordPress 2.5.1 and earlier might allow remote authenticated administrators to upload and execute arbitrary… WordPress after 2.5.1 Fix from $1,9502008-05-21 HIGH 7.5 CVE-2008-2146 wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attacke… WordPress after 2.2.2 Fix from $1,9502008-05-12 HIGH 7.5 CVE-2008-2034 SQL injection vulnerability in wp-download_monitor/download.php in the Download Monitor 2.0.6 plugin for WordPress allows remote attackers to execute… Download Monitor Plugin Mitigation only Fix from $1,9502008-04-30 HIGH 7.5 CVE-2008-1930EPSS 5% The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote … WordPress Patch available Fix from $1,9502008-04-28 HIGH 7.5 CVE-2008-1982 SQL injection vulnerability in ss_load.php in the Spreadsheet (wpSS) 0.6 and earlier plugin for WordPress allows remote attackers to execute arbitrar… Wpss after 0.6 Fix from $1,9502008-04-27 HIGH 7.5 CVE-2008-1646 SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands … Wp Download No fix yet Fix from $1,9502008-04-02 HIGH 7.5 CVE-2008-1059EPSS 48% PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers … Sniplets Plugin No fix yet Fix from $1,9502008-02-28 HIGH 7.5 CVE-2008-1060EPSS 44% Eval injection vulnerability in modules/execute.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary… Sniplets Plugin No fix yet Fix from $1,9502008-02-28 HIGH 7.5 CVE-2008-0939 Multiple SQL injection vulnerabilities in wppa.php in the WP Photo Album (WPPA) before 1.1 plugin for WordPress allow remote attackers to execute arb… Photo Album Plugin No fix yet Fix from $1,9502008-02-25 HIGH 7.5 CVE-2008-0845 SQL injection vulnerability in wp-people-popup.php in Dean Logan WP-People plugin 1.6.1 for WordPress allows remote attackers to execute arbitrary SQ… Dean Logan Wp People Plugin Mitigation only Fix from $1,9502008-02-20 HIGH 7.5 CVE-2008-0682 SQL injection vulnerability in wordspew-rss.php in the Wordspew plugin before 3.72 for Wordpress allows remote attackers to execute arbitrary SQL com… Wordspew after 3.71 Fix from $1,9502008-02-12 HIGH 7.5 CVE-2008-0683 SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to exec… St Newsletter Plugin No fix yet Fix from $1,9502008-02-12 MEDIUM 6.4 CVE-2008-0664 The XML-RPC implementation (xmlrpc.php) in WordPress before 2.3.3, when registration is enabled, allows remote attackers to edit posts of other blog … WordPress Patch available Fix from $1,6002008-02-08 HIGH 7.5 CVE-2008-0507 SQL injection vulnerability in adclick.php in the AdServe 0.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the … Adserve No fix yet Fix from $1,9502008-01-31 HIGH 7.5 CVE-2008-0520 Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote attackers to execute arbitrary S… Wassup Plugin after 1.4.3 Fix from $1,9502008-01-31 MEDIUM 6.8 CVE-2008-0508 Cross-site request forgery (CSRF) vulnerability in deans_permalinks_migration.php in the Dean's Permalinks Migration 1.0 plugin for WordPress allows … Permalinks Migration Plugin Patch available Fix from $1,6002008-01-31 HIGH 7.5 CVE-2008-0490 SQL injection vulnerability in functions/editevent.php in the WP-Cal 0.3 plugin for WordPress allows remote attackers to execute arbitrary SQL comman… Wp Cal Plugin No fix yet Fix from $1,9502008-01-30 MEDIUM 6.8 CVE-2008-0388 SQL injection vulnerability in the WP-Forum 1.7.4 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the user paramet… Wp Forum No fix yet Fix from $1,6002008-01-23 HIGH 7.5 CVE-2008-0222EPSS 8% Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remote attackers to upload and ex… Filemanager No fix yet Fix from $1,9502008-01-10 HIGH 7.5 CVE-2008-0194 Directory traversal vulnerability in wp-db-backup.php in WordPress 2.0.3 and earlier allows remote attackers to read arbitrary files, delete arbitrar… WordPress after 2.0.3 Fix from $1,9502008-01-10 MEDIUM 5.0 CVE-2008-0191 WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, wh… WordPress Mitigation only Fix from $1,6002008-01-10 MEDIUM 5.0 CVE-2008-0195 WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive information via an empty value of the page parameter to certain PHP scripts … WordPress after 2.0.11 Fix from $1,6002008-01-10 MEDIUM 5.0 CVE-2008-0196 Multiple directory traversal vulnerabilities in WordPress 2.0.11 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in (1)… WordPress after 2.0.11 Fix from $1,6002008-01-10 MEDIUM 5.0 CVE-2007-6369EPSS 8% Multiple directory traversal vulnerabilities in resize.php in the PictPress 0.91 and earlier plugin for WordPress allow remote attackers to read arbi… Pictpress after 0.91 Fix from $1,6002007-12-15 MEDIUM 6.8 CVE-2007-6318EPSS 9% SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the… WordPress No fix yet Fix from $1,6002007-12-12